Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_Dlls' = '<SYSTEM32>\D3DCompiler_3632.dll'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_Dlls' = '<SYSTEM32>\D3DCompiler_3632.dll,<SYSTEM32>\capiprovider32.dll'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\x6ykw2st5rins.vbs
- %WINDIR%\syswow64\d3dcompiler_3632.dll
- %WINDIR%\syswow64\capiprovider32.dll
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\X6ykw2St5rinS.vbs"' (со скрытым окном)
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\X6ykw2St5rinS.vbs"